1. Controller and contact information
Fennosteel Oy
Fennokatu 1, FI-39700 Parkano
fenno@fennosteel.com
2. Register name
Fennosteel Oy’s customer and stakeholder register.
3. Basis and purpose of the register
According to the EU General Data Protection Regulation, the legal basis for processing personal data is the controller’s legitimate interest (customer relationship) and the consent of the person visiting the site to collect anonymized tracking data (cookie settings/analysis cookies).
The purpose of personal data processing is communication with customers and potential customers, communication with stakeholders, and marketing and invoicing.
4. Data content of the register
Information stored in the register includes, for example: person’s name, position, contact information (phone number, e-mail address, address), company name, industry, billing information, and other information related to the customer relationship and the services ordered by the customer.
5. Regular sources of information
The information stored in the register is received from the customer, potential customer or various stakeholders via e-mail, telephone, social media services, contracts, meetings and other situations where the customer, potential customer or representative of the stakeholder group discloses their information.
6. Regular transfers of data and transfer of data outside the EU or EEA
Information is not regularly disclosed to other parties. Information can be published to the extent agreed with the customer.
Data can also be transferred by the controller outside the EU or EEA. Data will not be transferred to the United States without the express consent of the data subjects.
7. Basics of register protection
The customer register is only in electronic form and the devices and software are properly protected and care is taken in handling. When registry data is stored on Internet servers, the physical and digital data security of their hardware is taken care of accordingly. The registrar ensures that all information stored in the register is treated confidentially and only by those employees and partners whose job description it is.
8. Right of inspection and right to demand correction of information
Every person in the register has the right to check their information stored in the register and demand the correction of any incorrect information or the completion of incomplete information. If a person wants to check the information stored about him or demand correction, the request must be sent in writing to the controller. If necessary, the registrar may ask the requester to prove his identity. The controller responds to the information requester within the time stipulated in the EU data protection regulation (generally within a month).
9. Other rights related to the processing of personal data
A person in the register has the right to request the removal of personal data about him from the register (“the right to be forgotten”). Those registered also have other rights according to the EU’s General Data Protection Regulation, such as limiting the processing of personal data in certain situations. Requests must be sent directly and personally by e-mail to the controller. If necessary, the registrar may ask the requester to prove his identity. The controller responds to the customer within the time stipulated in the EU data protection regulation (generally within a month).
